Out of Bounds Read Flaw in libssh2 Affects SSH Functionality
CVE-2019-3862
7.3HIGH
What is CVE-2019-3862?
An out of bounds read flaw in libssh2 prior to version 1.8.1 allows remote attackers to exploit how SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. This vulnerability can potentially lead to Denial of Service attacks or unauthorized reading of client memory data when a compromised SSH server is involved.
Affected Version(s)
libssh2 1.8.1
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
